Bug#703281: rygel security issue

2013-04-29 Thread n8fer
Ok I got a full analyse of the behaviour: (Tested with debian wheezy rc2. each test was performed on a fresh installation) how to activate rygel after triggering the bug: starting and closing rygel for the first time (without changing the checkbox) this triggers the bug. full start and stop

Bug#703281: rygel security issue

2013-04-28 Thread n8fer
> Can partially confirm, but all that this does is setting the checkmark > in the UI. While this is confusing, it doesn't actually launch Rygel or > create the symlink necessary to autostart Rygel; no media is shared by > accident just by launching rygel-preferences twice. I have spend some time

Bug#703281: rygel security issue

2013-04-21 Thread Andreas Henriksson
Hello Michael Karcher! On Sun, Apr 21, 2013 at 02:53:27PM +0200, Michael Karcher wrote: > This behaviour is caused by the global (system wide) configuration file > /etc/rygel.conf containing "upnp-enabled=true". [...] > A short-term fix would be to ship with "upnp-enabled=false" in the global > co

Bug#703281: rygel security issue

2013-04-21 Thread Michael Karcher
Package: rygel Version: 0.14.3-2 Followup-For: Bug #703281 This behaviour is caused by the global (system wide) configuration file /etc/rygel.conf containing "upnp-enabled=true". That file is used as template for the local (user specific) configuration file, which is written when you exit rygel-pr

Bug#703281: rygel security issue

2013-04-20 Thread John Paul Adrian Glaubitz
Since the problem is reproducible only when rygel-preferences is run for the first and second time consecutively (no ~/.config/rygel.conf initially exists), it must be related to the fact that rygel-preferences cannot find an existing configuration file and hence a default setting for the shari

Bug#703281: rygel security issue

2013-03-18 Thread mike . a . oliver
On Sunday, March 17, 2013 7:20:01 PM UTC-4, deb...@lavabit.com wrote: > Package: rygel > > Version: 0.14.3-2 > > Severity: important > > > > > > Dear Maintainer, > > > > > > The current version of rygel which is part of Debian Wheezy contains a > > possibly security issue: > > > > W

Bug#703281: rygel security issue

2013-03-18 Thread debmail
Package: rygel Version: 0.14.3-2 Severity: important > On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: > [...] >> When starting rygel preferences a second time (without having changed >> the >> preferences) the sharing option is activated. > > Unreproducible. The bug is on

Bug#703281: rygel security issue

2013-03-18 Thread debmail
> On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: > [...] >> When starting rygel preferences a second time (without having changed >> the >> preferences) the sharing option is activated. > > Unreproducible. The bug is only reproducible when using rygel the first time. When o

Bug#703281: rygel security issue

2013-03-17 Thread Andreas Henriksson
On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: [...] > When starting rygel preferences a second time (without having changed the > preferences) the sharing option is activated. Unreproducible. > > Therefore everyone starting rygel preferences for once, activates the uPnP >

Bug#703281: rygel security issue

2013-03-17 Thread debmail
Package: rygel Version: 0.14.3-2 Severity: important Dear Maintainer, The current version of rygel which is part of Debian Wheezy contains a possibly security issue: When starting rygel preferences a second time (without having changed the preferences) the sharing option is activated. Therefo